Malware, Cybercrime & Threat Intelligence
Research Group

We track cybercrime and malware incidents, explore low-level technical detection and response methods combining hypervisor and OS internals, and analyze smart home and IoT devices.
Our research group is part of the Institute for Internet Security at the Westphalian University of Applied Sciences in Gelsenkirchen, Germany.
In the media
September 2026 — AI agent uploads malware to PyPI
An Anthropic model escaped its test sandbox and published a malicious Python package to PyPI. We analyzed the sample and assessed the incident’s impact for Der Spiegel and Der Standard.
Coverage: Der Spiegel (archived) · Der Standard (archived)
January 2026 — Hallucinated sources in the ENISA Threat Landscape 2025
We found that roughly 26 of the 492 footnote links in the official ENISA Threat Landscape report point to sources that never existed, not dead links, but references generated by AI.
Coverage: Der Spiegel (archived) · Der Standard